DNS Doctoring with a cisco router
I'm wondering if there's a command that is similar to the PIX
firewall's ALIAS command on a Cisco Router. Can anyone help me here?
On Tue, 25 Nov 2003 16:32:22 -0600, Cool Guy Bri wrote:
> I'm wondering if there's a command that is similar to the PIX firewall's
> ALIAS command on a Cisco Router. Can anyone help me here?
According to Document 26704, NAT Frequently Asked Question, it does DNS
doctoring by default.
Thank You for your help Rik!
Rik Bain <email@example.com...Cisco!! Cisco!! Cisco!!
Given there has uncharacteristically been no post here from Doc Dwarf for
nearly 4 weeks, and he is (also uncharacteristically) not responding to
private mail, there seems to be some reason for concern.
He did mention some health problems a little while ago.
Doc, if you are seeing this, please know you are missed here and (if it is
appropriate) every wish for a speedy recovery.
"I used to write COBOL...now I can do anything."
On 8/24/2011 6:42 PM, Pete Dashwood wrote:
> Given there has uncharacteristically been no post here from Doc Dwarf for
> nearly 4 wee...DNS doctoring.
we have a web server inside our LAN.
We have PIX32 between the world and us.
I know that traffic can not come from one interface and flow to the same interface (in this case the inside one)
This mean that internal clients can not access web server (e.g. www.pincopallo.it) because the DNS response return an
external IP but the real machine (192.168.31.26) is inside the lan.
We have just insert the static and conduit statement for internet people to access our web server.
static (inside,outside) IP_of_www.pincopallo.it 192.168.31.26 netmask 255.255.255.255 0 0
conduit permit tcp host ...DNS and cisco routers
Hi gents, my domain machines don't work correctly with my dns, but
they do with my dhcp , so I wonder if there is any parameter such as
ip helper-address for dhcp, that should be configured to make dns work
in different connected networks.
Thanks in advance .
In article <firstname.lastname@example.org>, "Sako" <email@example.com> writes:
> Hi gents, my domain machines don't work correctly with my dns, but
> they do with my dhcp , so I wonder if there is any parameter such as
> ip helper-address for dhcp, that should be con...DNS Relay on Cisco?
I tried to use a cisco router as a dns relay for my LAN, but without
success. I've set
# ppp ipcp dns request
to learn the name server from the ppp session, and a
# ping www.google.de
I read about a "ip dns server" command, but the IP ADSL PLUS IOSse I've
tried (c1700-sy7-mz.124-3b.bin, c1700-sy7-mz.123-7.XR6.bin) don't
accept this command in conf t. It's a Cisco 1721.
Thanks in advance,
...DNS Doctoring with PIX
I have upgraded to PIX 6.3(4) and I am trying to use the DNS command in my
STATIC to access my inside server via domain name. I do not use an internal
My question is, am I missing some other command, sysopt or fixup to make
this work? The static I have does work for outside-inside traffic, but
still does not 'doctor' the DNS inquiries for inside use. I do have the
fixup protocol dns maximum-length 512 statement. There really isn't a lot
of info on using this command in a static. I know there is an alias
command, but I only have one IP address that I need to...DNS on Cisco RAS
I configured Cisco 3600 to work as RAS & I added the :
ip name-server x.x.x.x
ip name-server y.y.y.y
for the DNSs to be used by dialup clients.
but I noticed that when the client dial-in, they get wrong IPs for the
DNS : 192.168.1.1 which are not the correct IPs of our DNSs.
On Thu, 20 Nov 2003 16:31:02 -0600, hakim soso wrote:
> I configured Cisco 3600 to work as RAS & I added the : ip name-server
> ip name-server y.y.y.y
> for the DNSs to be used by dialup clients. but I noticed that when the
> client dial-in, they get wrong IPs for the DNS : 192.168.1.1 wh...DNS doctoring, alias .
Does the DNS doctoring work without specifing protocols and ports or does it with them as well?
Are internal DNSes needed for the doctoring to work properly or is it the same thing to have clients with external DNSes
specified and answers from them are anyway translated?
"AM" <firstname.lastname@example.org> wrote in message
> Does the DNS doctoring work without specifing protocols and ports or does
it with them as well?
yes, you can use the alias command completly "stand-alone"
look at the Cisco doc for "understanding th...DNS doctoring 300001
I have problem with DNS doctoring in PIX 6.3(3)
I set alias command and sysopt noproxyarp inside
and it doesn't work.
Out customer has linux with masquarade and he has static and
for outside DNS they see this domain as static IP
and they can't achieve this server. Then I try set alias command.
Any known bug or sth else ?
...DNS Doctoring conversion?
Currently, we are using the ALIAS command for DNS doctoring to access
private IP resources inside the network that are also accessed from
outside the network:
alias (inside) 10.y.y.249 209.x.x.35 255.255.255.255
I know that Cisco has said that they are only maintaining this command
for backward compatability and recommend going to the STATIC entry.
But, I am confused by this entry on how to properly implement. Any
insight would help on the proper structure to continue being able to
provide DNS doctoring access from the inside of the network.
I am running a PIX 515 6.3(3)
On Mon, 10 Nov 2...cisco 2500 forward to dns
I have a cisco 2500 router that i am trying to add to my network. I've
the cisco router to my linksys router (which is my main router) and I
am able to telnet to the cisco router, configure etc...I am not able to
get DNS working on the cisco router. I can ping all of the other
computers and the linksys router from the cisco router. I've tried
my isp name servers to the cisco router, but that's not working. I
tried adding my linksys
router as a name server on my cisco router and i am able to ping from
the cisco router
and i see the translation happe...DNS Record in CISCO Router
I want to configure DNS Record in CISCO Router.
I am using Router as internet server with DNS.
If i configure it there users can connect to my configured sites
Could you be more specific? You need to let internet users access your
web-servers. Am I correct?
Connecting IT Pros from all over the World
On 11 =CD=EF=DD, 10:32, Ts8060 <ts.8...@gmail.com> wrote:
> I want to configure DNS Record in CISCO Router.
> I am using Router as internet server with DNS.
> If i configure it there u...Cisco 1700 and DNS cache
Is it possible to set Cisco 1721 with IOS IP Plus
to catch all DNS queries. I mean that Cisco would be
asking it't primary DNS first time client is asking router,
but second time and next, only router response to that
DNS query. How to do it?
...Verifying DNS with Cisco 837
I have a Cisco 837 Router and have configured it to obtain DNS from the
ISP via the "ppp ipcp dns request" command on my Dialer interface.
I am able to resolve addresses without problems, but would like to
verify what dns servers were assigned to me.
Does anyone know the "show" command or eqivalent that displays this?
...Cisco or not Cisco for IDS
I need your point of view on this. I have to setup a IDS network and I
do not know how to start my investigations on it. Well, it seems
that Cisco has IDS appliances but everybody around me says that I also
have to have a look at ISS Proventia ( www.iss.net/proventia ). Is the
Cisco Management Application for IDS as easy as Site_Protector? How
are the signature updates provided, by Cisco itself or through the
If the bandwidth I have to monitor is about 200Mbits, what would be
your choice is the Cisco catalogue? In the ISS catalogue?
Alabama Circus wrote:
&...What are files Z80.SYS, Z80CCP.SYS and PRMTVPVT.SYS for?
Had a good Christmas this weekend?
I came across diskettes with "Mailmerge 3.0 and Calcstar version 1.45 for CP/M
8080", that seem to be for a Dec Rainbow machine.
Besides a Mailmerge overlay and the Calcstar files, some CP/M and some CP/M-86
files, there are three files on the diskettes that I never have heard of before:
Z80.SYS, Z80CCP.SYS and PRMTVPVT.SYS.
There are no ASCII texts in PRMTVPVT.SYS.
The only ASCII text in Z80.SYS (at the end of the file) is "EI SPHLDI
XCHGPCHLXTHLRET HLT CMC STC CMA DAA RAR RAL RRC RLC NOP CPI ORI XRI ANI SBI IN
SUI OUT ACI ADI CALLJMP LDA...Cisco 877
-----BEGIN PGP SIGNED MESSAGE-----
I have DHCP and DNS configured on my Cisco 877 and have been trying to
get Dynmaic DNS updates running. Is this possible on an 877? If it is can
someone please point me to some documentation I can read?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.11 (FreeBSD)
-----END PGP SIGNATURE-----
> Hi all,
> I have DHCP and DNS configured on my Cisco 877 and h...Turn a Cisco Router into a DNS server
Does anybody know how to make a Cisco Router act as a DNS server? Let
me clarify that I'm not talking about relaying/forwarding DNS requests,
from the router to another system that resolves DNS. I want the router
to listen on port 53 for DNS queries; once the query is received the
router should look to its own host table (Both perm and cached entries)
and then return a name resolution (IP address) to the querying host.
"jsh3323" <email@example.com> wrote in message
> Does anybody know how to make ...Cisco VPN client intercepts DNS
I'm running the Cisco client on my Fedora Core 2 gateway to connect to a
peer site's Windows servers. However, I want to continue to use the BIND
DNS server on the gateway to connect to the Internet. When the VPN is up,
my DNS packets seem to get intercepted and replies come from the peer's DNS
server instead of the outside authoritative servers that were queried. What
can I do to get the client to leave my DNS alone? Is this a setting in my
peer's VPN server that needs adjusting? What would I need to ask for?
(I don't need the DNS to resolve the peer's servers. ...Cisco 801 (ISDN): DNS Relay
I've already written about my router and the ICMP problem, but I have one
On my old router, it acted as a sort of DNS relay. I added the internal ip
address of the router under the DNS server setting on the clients, and the
router relayed the requests to the name-servers given by the ISP.
I can add 'ip nameserver xxx.xxx.xxx.xxx' to the router, but this doesn't
seem to do the same thing. The router can resolve names, but it won't
resolve names for my clients (If you understand what I mean!). As a result,
I've had to add the namservers of the ISP to the...DNS resolution fails on Cisco 2821
I have a cisco 2821 Intergrated Router. I have set the DNS address to
our typical DNS and when I ssh into the cisco box I get DNS resolution
but from any machine or network plugged into the cisco 2821 it fails.
Here is my config as it is right now.
Using 9028 out of 245752 bytes
no service pad
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service sequence-...PIX DNS doctoring with 2003 server
A quick question guys.
I recently put a few firewalls in a customer premises with a static NAT
policy. Internally the clients were 192.168.1.x but extrenally they were
135.1.1.x statically mapped one for one. DNS always worked ok since there
were no servers on these sites - I accepted the limitaion that the machines
cannot ping by machine name. This worked loads of times. I then had
another site exactly like this but had a server as well as just client PC's.
The clients could not get their drive mappings on this server until I
clicked the DNS option against the static transatio...Dns doctoring/dnsmasq -V on bind?
After googeling a lot I kinda gave up and ended here.
Im running a bind server, where we have out .loc zone on and also use it for
We have our domains hosted @ our ISP's DNS-Servers.
Now recently management decided to migrate from cisco to
Now as you might know, there is a dns-doctoring feature on cisco devices,
that will rewrite ip addresses in dns-query-responses.
I found a nice non-cisco explanation by someone who had my problem some
> My dns server sits outside my firewall on the internet and answers queries